Show filters
923 Total Results
Displaying 261-270 of 923
Sort by:
Attacker Value
Unknown

CVE-2023-36089

Disclosure Date: July 31, 2023 (last updated February 25, 2025)
Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2023-37758

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
Attacker Value
Unknown

CVE-2023-37791

Disclosure Date: July 17, 2023 (last updated February 25, 2025)
D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.
Attacker Value
Unknown

CVE-2023-26616

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
Attacker Value
Unknown

CVE-2023-26613

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.
Attacker Value
Unknown

CVE-2023-26612

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
Attacker Value
Unknown

CVE-2023-26615

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
Attacker Value
Unknown

CVE-2023-32222

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
Attacker Value
Unknown

CVE-2023-32224

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
Attacker Value
Unknown

CVE-2023-32223

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.